Supporters of BTCPay Server have offered a 3 BTC recovery bounty after a security incident exposed LND wallet credentials, prompting the open-source Bitcoin payment project to warn users and issue guidance around the affected release.
Supporters of BTCPay Server have offered a 3 BTC recovery bounty after a security incident exposed LND wallet credentials, prompting the open-source Bitcoin payment project to warn users and issue guidance around the affected release.
Supporters of BTCPay Server have offered a 3 BTC recovery bounty after a security incident exposed LND wallet credentials, prompting the open-source Bitcoin payment project to warn users and issue guidance around the affected release.
The incident centers on BTCPay Server, the self-hosted Bitcoin and Lightning payment processor, and the exposure of credentials tied to LND, the Lightning Network Daemon used to run Lightning nodes. The details were published in a BTCPay Server security advisory covering version 2.4.2. For related coverage, see BTCPay Server supporters offer 3 BTC bounty after exploit.
A 3 BTC bounty has been floated as part of the response, aimed at recovering funds connected to the exploit. The offer sits alongside the project’s advisory as the community works to trace what was taken. For related coverage, see Trump Media Increases Bitcoin Holdings to 14,139 BTC From 9,542 in Q1.
Not every element of this story has been independently confirmed. The underlying research classifies the event as a security incident with only partial verification, so the exposure of LND credentials and the bounty should be read as the core confirmed thread, while granular figures on losses remain unsettled.
WHAT TO KNOW
Credential exposure is more serious than a routine software bug. A crash or display glitch is disruptive; leaked LND credentials can give an attacker the keys needed to move funds out of a Lightning node directly.
The people most exposed are BTCPay Server operators who self-host, including merchants accepting Bitcoin, node operators, and Lightning users whose hot-wallet balances sit online to route and settle payments. Because LND is a Lightning Network implementation, the incident lands squarely on Bitcoin’s payment stack rather than the broader crypto market.
That framing matters for how self-custody users read the event. Earlier coverage of this episode, including reporting that BTCPay Server confirmed funds were stolen in the exploit, underscores that this is an operational security failure with real balances at stake, not a theoretical vulnerability.
The clearest remediation signal so far is the advisory itself, tied to the 2.4.2 release, which is where operators should look for upgrade and mitigation steps. Follow-up reporting indicates the project moved to restrict remote Lightning access after attackers stole funds, a containment step that changes how remote nodes can connect.
Readers running affected setups should monitor maintainer updates for further patches and rotate any credentials that may have been exposed. The same urgency framed the earlier BTCPay emergency patch and its merchant-side security risk, which pointed operators toward immediate action rather than waiting.
For Lightning payment tooling more broadly, the open question is whether restricting remote access and recovering funds restores confidence among self-hosting merchants. The bounty and the access limits are the concrete steps to track, alongside any wallet-operator guidance surfaced as the exploit’s impact on Lightning payment servers becomes clearer.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Quick access to the site tools and map-driven utility pages.
Follow the core desks readers use most across Bitcoin, altcoins, mining, events, and sponsored coverage.
© 2026 BitcoinInfoNews.com. All rights reserved.
Independent Bitcoin and crypto coverage with public trust, policy, and newsroom pages available sitewide.